Sample viewer

vx.netlux.org/Virus.DOS.Lyceum.1832.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:26.502120645Z 187 PC: 13dd5 | UNKNOWN!
2018-12-17T23:02:26.514055942Z 42 PC: 13e15 | Get date 0x13e15: xor al, al
0x13e17: cmp dl, 0xd
0x13e1a: jne 0x13e1e
0x13e1c: dec al
0x13e1e: mov byte ptr [0x736], al
0x13e21: mov ax, 0x3508
0x13e24: int 0x21
0x13e26: mov word ptr [0x728], bx
0x13e2a: mov word ptr [0x72a], es
0x13e2e: mov al, 9
0x13e30: int 0x21
0x13e32: mov word ptr [0x72c], bx
0x13e36: mov word ptr [0x72e], es
0x13e3a: mov al, 0x21
0x13e3c: int 0x21
0x13e3e: mov word ptr [0x730], bx
0x13e42: mov word ptr [0x732], es
0x13e46: mov dx, 0xd6
0x13e49: mov ax, 0x2508
0x13e4c: int 0x21
2018-12-17T23:02:26.516573651Z 53 PC: 13e26 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:02:26.51806862Z 53 PC: 13e32 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:02:26.520405275Z 53 PC: 13e3e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:26.522315648Z 37 PC: 13e4e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:02:26.523405989Z 37 PC: 13e55 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:02:26.524572483Z 37 PC: 13e5c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:26.525958323Z 9 PC: 13dc6 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14214,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:09.111136892Z 187 PC: 13dd5 | UNKNOWN!
2018-12-25T12:40:09.112661448Z 42 PC: 13e15 | Get date 0x13e15: xor al, al
0x13e17: cmp dl, 0xd
0x13e1a: jne 0x13e1e
0x13e1c: dec al
0x13e1e: mov byte ptr [0x736], al
0x13e21: mov ax, 0x3508
0x13e24: int 0x21
0x13e26: mov word ptr [0x728], bx
0x13e2a: mov word ptr [0x72a], es
0x13e2e: mov al, 9
0x13e30: int 0x21
0x13e32: mov word ptr [0x72c], bx
0x13e36: mov word ptr [0x72e], es
0x13e3a: mov al, 0x21
0x13e3c: int 0x21
0x13e3e: mov word ptr [0x730], bx
0x13e42: mov word ptr [0x732], es
0x13e46: mov dx, 0xd6
0x13e49: mov ax, 0x2508
0x13e4c: int 0x21
2018-12-25T12:40:09.116327012Z 53 PC: 13e26 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:40:09.118080687Z 53 PC: 13e32 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:40:09.119851826Z 53 PC: 13e3e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:09.122560621Z 37 PC: 13e4e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:40:09.124255088Z 37 PC: 13e55 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:40:09.125948552Z 37 PC: 13e5c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:09.128506395Z 9 PC: 13dc6 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":13,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14214,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:09.323630687Z 187 PC: 13dd5 | UNKNOWN!
2018-12-25T12:40:09.325085682Z 42 PC: 13e15 | Get date 0x13e15: xor al, al
0x13e17: cmp dl, 0xd
0x13e1a: jne 0x13e1e
0x13e1c: dec al
0x13e1e: mov byte ptr [0x736], al
0x13e21: mov ax, 0x3508
0x13e24: int 0x21
0x13e26: mov word ptr [0x728], bx
0x13e2a: mov word ptr [0x72a], es
0x13e2e: mov al, 9
0x13e30: int 0x21
0x13e32: mov word ptr [0x72c], bx
0x13e36: mov word ptr [0x72e], es
0x13e3a: mov al, 0x21
0x13e3c: int 0x21
0x13e3e: mov word ptr [0x730], bx
0x13e42: mov word ptr [0x732], es
0x13e46: mov dx, 0xd6
0x13e49: mov ax, 0x2508
0x13e4c: int 0x21
2018-12-25T12:40:09.327215229Z 53 PC: 13e26 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:40:09.328283725Z 53 PC: 13e32 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:40:09.33043536Z 53 PC: 13e3e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:09.332343514Z 37 PC: 13e4e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:40:09.333386892Z 37 PC: 13e55 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:40:09.358430913Z 37 PC: 13e5c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:09.359671063Z 9 PC: 13dc6 | Display string (String= 'Hello - Copyright S & S International, 1990 ')